Skip to main content

Government

Penetration testing & CERT-In audit for FS&CW Dept, Govt of Odisha

Assessment of the public distribution system platform covering ration entitlement and beneficiary data.

Scale

Statewide PDS platform

Food Supplies & Consumer Welfare Dept, Government of Odisha

  • Penetration Testing
  • CERT-In Audit
Penetration testing & CERT-In audit for FS&CW Dept, Govt of Odisha

The brief

Penetration testing and CERT-In audit for the Food Supplies and Consumer Welfare Department's public distribution systems.

What we did

  • External and authenticated penetration testing of departmental systems
  • Application and API assessment of the distribution workflow
  • Infrastructure hardening and configuration review
  • CERT-In audit reporting with retesting to closure

Public distribution is one of the least glamorous and most consequential systems a state runs. If it fails, people do not receive food. That framing shaped the assessment: availability and integrity mattered as much as confidentiality, which is not the usual weighting.

Integrity over confidentiality

On most platforms we assess, the worst outcome is data leaving. Here, the worst outcome is data changing: an entitlement altered, an allocation misdirected, a record of collection created that did not happen. We tested for write paths and state transitions with the same rigour usually reserved for read access.

Penetration testing, not just scanning

The engagement was scoped as penetration testing rather than a vulnerability assessment, which means the work was manual and the objective was demonstrated impact rather than a list of potential issues. Findings were carried to proof, with reproduction steps, and rated on what an attacker could actually achieve rather than on a generic score.

Infrastructure

Departmental estates accumulate. Systems built for one programme stay online after it ends, and the forgotten ones are rarely patched. Part of the value of an external test on a government estate is simply establishing what is actually exposed, which is regularly more than the asset register says.

What was handed over

Penetration test report with proof of exploitation and impact, the CERT-In format audit deliverable, remediation guidance sequenced by risk, and retesting.

Engagement
Penetration test and CERT-In audit
Emphasis
Integrity of distribution records
Retesting
Included until closed

Engagement detail is summarised. Specific findings, payloads and architecture remain confidential under our client agreements.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.